The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-101267 | 2.7 LOW | Revenue information leak |
| CVE-2026-101270 | 2.1 LOW | HTML injection |
| CVE-2026-101271 | 2.1 LOW | OAuth credentials not disabled when application is disabled |
| CVE-2026-101268 | 1.7 LOW | Customer session fixation |
| CVE-2026-101266 | 1.3 LOW | Checkout validation bypass |
暂无评论